Reference
Google Workspace security checklist
A Google Workspace security checklist should start with the 4 controls that close the most common breach paths: enforced 2-step verification, restricted third-party app access, external sharing limits on Drive, and an alert on super admin role changes. Everything else is refinement on top of those.
| 1. 2-step verification | Enforced for all users, security keys for admins |
|---|---|
| 2. Third-party app access | Move from unrestricted to allow-listed OAuth scopes |
| 3. External Drive sharing | Warn or restrict outside the domain, disable link-anyone by default |
| 4. Super admin alerts | Alert centre rule on role grant, plus fewer than 4 super admins |
| 5. Email authentication | SPF, DKIM and DMARC at enforcement, not p=none |
| 6. Recovery paths | Admin recovery contacts verified and less privileged accounts for daily use |
Why the order matters more than the list
Checklists fail because they are worked alphabetically. The account takeover route in nearly every incident we see is a password reused elsewhere plus an OAuth grant to a tool nobody reviewed, so those two items belong first regardless of how many other settings are open.
Working in risk order also means an admin who runs out of time on a Friday has still closed the expensive paths rather than the cosmetic ones.
The controls people skip
Super admin count is the one most often ignored. Tenants of sixty seats routinely carry six or seven super admins, several belonging to former contractors, and each is a full-tenant compromise waiting for one phishing click.
The second is alerting. Settings without alerts are a snapshot; a rule that emails on role change or on suspicious login turns the configuration into something you notice being undone.
- Cap super admins and give day-to-day work a delegated role
- Enable alert centre rules for role grants and suspicious sign-ins
- Review OAuth grants quarterly rather than at incident time
- Turn off IMAP and POP where nobody uses them
- Check that every admin has a verified recovery method
What we see that others don't say
Across the Workspace tenants we assess, unreviewed third-party OAuth grants outnumber disabled 2-step verification accounts, yet almost no checklist places app access above password policy.
What this doesn't cover
- This checklist covers Workspace tenant configuration, not endpoint security, network controls or the applications outside Workspace.
- Some controls listed require Business Plus or Enterprise; the checklist notes the risk, not the licence you hold.
Want this done for you?
Three fields. We come back with whether this is a 20-minute fix or a project, and what it costs.
Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.
Questions we get asked
- How many super admins should a Google Workspace tenant have?
- Fewer than four for most organisations, with two as a working minimum so nobody is locked out. Daily administration should run through delegated roles rather than super admin accounts.
- What is the single highest-value Workspace security change?
- Enforced 2-step verification for every user, with hardware security keys on admin accounts. It removes the credential-reuse path that begins most of the account compromises we are called to investigate.
How this page is verified
Reviewed by Workspace Migration Services security desk, Workspace security and compliance reviewers. Last checked .
- Control names and console locations verified against Google's security checklist documentation at the review date.
- Ordering drawn from the initial access paths recorded in our own incident work.
Sources you can check
Related pages
Want the checklist run against your tenant?
A security review works these controls in order, records the current state of each with evidence, and returns a change list your admin can apply in an afternoon.